Cyber Incident Victim: Lifespan Services
Timeline
Summary
Lifespan Physicians Group experienced an unauthorized intrusion into its historic server network that exposed the personal information of over 290,000 patients. The compromised data included names, dates of birth, contact details, Social Security numbers, driver’s license numbers, financial account information, and medical records, affecting individuals associated with Hawthorn Medical Associates, Saint Anne’s Hospital, and Morton Hospital. State attorneys general were notified, and affected individuals were informed several months after the intrusion.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On December 15 and 16 of 2025 an unauthorized actor gained access to Lifespan Physicians Group’s historic server network, compromising systems associated with its affiliated entities Hawthorn Medical Associates, Saint Anne’s Hospital and Morton Hospital. The intrusion remained undisclosed until July 16 2026 when Lifespan notified the Massachusetts Office of the Attorney General and the Vermont Attorney General of the breach. According to the notifications, 290,357 residents of Massachusetts and 86 residents of Vermont were identified as having their personal information exposed. The affected individuals are patients of the aforementioned medical groups that operate under the Brown Health Medical Group‑MA brand. The delay between the breach discovery and public notification spanned approximately seven months, a period noted in the disclosures as potentially violating state and federal reporting requirements. No further technical details about the method of intrusion or the specific servers involved were provided in the public statements.

The data that may have been compromised includes names, dates of birth, contact information, compensation or payroll details, licensure or credentialing records, medical or disability‑related information, Social Security numbers, driver’s license numbers or other government‑issued identification numbers, credit or debit card numbers and financial account information. Because of the breadth of data exposed, individuals whose information was accessed face an elevated risk of identity theft, financial fraud and other privacy violations as stated in the breach notice. The notice also indicates that affected persons may be entitled to seek monetary damages and to request injunctive relief compelling Lifespan to improve its cybersecurity practices. The breach notice further explains that the compromised information could be used to open fraudulent accounts, obtain unauthorized medical services or manipulate financial records. No evidence of actual misuse of the data has been disclosed in the available reports, and the notifications do not identify the threat actor or attribute the intrusion to any particular group. The incident underscores the challenges faced by healthcare organizations in safeguarding legacy systems that retain historical patient records.
